CVE-2020-2832 is a high-severity vulnerability affecting Oracle One-to-One Fulfillment versions 12.1.1-12.1.3, specifically within its Print Server component. This easily exploitable vulnerability allows an unauthenticated attacker to compromise the system via HTTP, requiring human interaction from a non-attacker. Successful exploitation can lead to unauthorized access to critical data, complete data access, and unauthorized data modification within Oracle One-to-One Fulfillment, with potential impact on additional products. The CVSS 3.0 Base Score is 8.2, indicating significant confidentiality and integrity impacts. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1.1, <= 12.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:one-to-one_fulfillment:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.